Learn about CVE-2017-8812, a vulnerability in MediaWiki versions before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allowing remote attackers to inject > characters through the id attribute of a headline.
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
Understanding CVE-2017-8812
Remote attackers can inject > (greater than) characters through the id attribute of a headline in MediaWiki versions prior to 1.27.4, 1.28.x prior to 1.28.3, and 1.29.x prior to 1.29.2.
What is CVE-2017-8812?
CVE-2017-8812 is a vulnerability in MediaWiki versions before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 that allows remote attackers to inject > characters through the id attribute of a headline.
The Impact of CVE-2017-8812
Technical Details of CVE-2017-8812
MediaWiki versions before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 are affected by this vulnerability.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take:
Patching and Updates